Version
0.6.5
OS
Microsoft Windows 11 Pro
10.0.26100 Build 26100
Describe the bug
McAffee antivirus detects vfox.exe as a trojan on access and deletes it.
Analyzer / Detector
| Analyzer content creation date |
2025.4.23. 9:02 AM |
| Product name |
McAfee Endpoint Security |
| Product version |
10.7.0.3497 |
| McAfee GTI query |
Yes |
| Task name |
On-Access Scan |
| Feature name |
On-Access Scan |
Threat
| Action taken |
Delete |
| Threat category |
Malware detected |
| Threat detected on creation |
No |
| Threat event ID |
1027 |
| Threat handled |
Yes |
| Threat name |
Artemis!606BC678830E |
| Threat severity |
Critical |
| Threat timestamp |
2025.4.25. 12:46 PM |
| Threat type |
Trojan |
Source
| Source hostName |
- |
| Source process name |
C:\Program Files\PowerShell\7\pwsh.exe |
Target
| Target access time |
2025.4.25. 12:46 PM |
| Target create time |
2025.3.11. 4:29 PM |
| Target file size (bytes) |
12503552 |
| Target hash |
606bc678830e835d9838bbcde33404db |
| Target host name |
- |
| Target modify time |
2025.4.10. 2:19 PM |
| Target name |
vfox.exe |
| Target path |
C:\Program Files\vfox |
| Target user name |
- |
Other
| Cleanable |
Yes |
| Detection message |
McAfee Endpoint Security detected a threat. |
| Detection quarantine ID |
{9A910F85-FCCF-48B9-82D2-B8DA7E7B746B} |
| Duration before detection (days) |
14 |
| Description |
- ran C:\Program Files\PowerShell\7\pwsh.exe, which attempted to access C:\Program Files\vfox\vfox.exe. The Trojan named Artemis!606BC678830E was detected and deleted. |
| First action status |
Succeeded |
| First attempted action |
Delete pending |
| Second attempted action |
n/a |